Bombarded by Trojan/vundo threats, really struggling!

Discussion in 'Malware Help (A Specialist Will Reply)' started by chaotix, Apr 9, 2010.

  1. chaotix

    chaotix Private E-2

    I have been fighting a losing battle the past 3 days against an onslaught of malware/trojan threats, i finally stumbled across your forums and you are my last hope before i consider a full reinstall, i started following your steps to remove malware: READ & RUN ME FIRST. Malware Removal Guide. However i fell at the first hurdle upon installing and scanning with superantispyware it detected approximately 16 threats, it went to the quarantine and delete stage and asked me to reboot i did so however upon reboot i got the blue screen and windows refused to boot, i had to restore to last known good configuration...
    i have done so, and am unsure of the best course of action, do i run superantispyware again and see what happens?
    if it is any help, i do remember some descriptions of the agents, trojan agent/Gen-Nullo[Short], and trojan agent rootkits, when googled came up as vundo threats, any help would be most appreciated!
     
  2. chaotix

    chaotix Private E-2

    slight update, this may delay my reply i guess but wanted to post logs to you guys, even though superantispyware after reboot caused windows to not boot at all, after restoring to last known good configuration the log file was there from the scan so i have managed to attach that, all other scans completed and ran properly except for combofix which got stuck after completing stage 2, literally it would stall for hours and i have no clue why! after running all these am noticing the same little windows emerge when i browse the net taking me to really weird ad sites, im not sure if the inability to reboot and having to restore to last known good configuration might have affected the removal of some malicous files? if you could take a look at the log and perhaps suggest something i would be most appreciative. Im not sure if this may help you guys but also during these past 3 days, sometimes i would run virus scans and malware scans and all would say clean, but after 1 reboot and browsing the net for a few minutes (nothing dodgy just email and youtube) windows would pop up and after a virus and malware rescan more items would have appeared, anyway if you could make sense of any of this im kinda lost at moment!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    In order to run ComboFix, you needed to shutdown all protection software. Did you do this and get McAfee and ZoneAlarm shutdown?

    Speaking of ZoneAlarm, you need to uninstall it immediately. Yes that means right now. As stated in the beginning of the REAZD & RUN ME instructions, you must only have one firewall installed and you have two ( ZoneAlarm and McAfee ).


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O15 - Trusted Zone: http://www.macho****er.com

    After clicking Fix, exit HJT.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. chaotix

    chaotix Private E-2

    Hey there Chaslang thank you for the response. I uninstalled zone alarm as instructed so now only McAfee antivirus and firewall is running.
    I deleted the 3 lines as instructed no problems there, removed windows messenger (think it worked), and ran that fixme reg file. I have just cleaned out all the temp files and ran cccleaner and am attaching logs for avenger and MGtools to this reply, i am still occassionally noticing new tabs opening with IE and firefox, but no where near as frequent as they were which is a positive sign, if you can see any problems in the logs let me know!
     

    Attached Files:

  5. chaotix

    chaotix Private E-2

    ok i have managed to get combofix to run after uninstalling zone alarm, and totally disabling mcAfee, i am just posting that log here as well, sorry its a little late but i got there in the end!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you create the below policies?
    Do you have any Disk Emulation Software running? Like Daemon Tools or similar? If so, you needed to run step 6 of the READ & RUN ME.


    Please download HelpAsst_mebroot_fix.exe by noahdfear and save it to your Desktop
    • Double click HelpAsst_mebroot_fix.exe to run it and follow any prompts.
      • If the tool detects an mbr infection
        • please allow it to run mbr -f and shutdown your computer.
        • Upon restarting, please wait about 5 minutes after bootup, and then click Start>Run and type the following bolded command, then hit Enter.
          • helpasst -mbrt
        • Make sure you leave a space between helpasst and -mbrt
        • When it completes, a log will open.
        • Attach this log to your next message.
      • If the tool DOES NOT detect an mbr infection and completes running:
        • Click Start>Run and type the following bolded command, then hit Enter.
          • mbr -f
        • Make sure you leave a space between mbr and the -f
        • Now, please do the Start>Run>mbr -f command a second time.
        • Now shut down the computer (do not restart, you must shut it down), wait a few minutes then start it back up.
        • Give it about 5 minutes after the bootup and then click Start>Run and type the following bolded command, then hit Enter.
          • helpasst -mbrt
        • Make sure you leave a space between helpasst and -mbrt
        • When it completes, a log will open.
        • Attach this log to your next message.
    No matter what happens with the above, attach the above logs and then immediately continue with the below in normal boot mode!


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the log from helpasst
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 11, 2010
  7. chaotix

    chaotix Private E-2

    hey chaslang
    ok in regards to those policies i did NOT make them, google chrome refuses to run completely may these policies be responsible?? if so how is best way to remove them??

    I have noticed some slightly more serious problems with booting now, when i first switched on my comp this morning i got blue screen and it restarted, only when i selected "start windows normally" would it open windows. Again after shutting down my computer for the boot fix stages the same thing, blue screen and only loading when i select "start windows normally".
    i ran both the boot fix thing and MG tools and have attached both logs to this message, im hoping you can help me things are looking grim!
    I am from the UK and heading to san francisco tomorrow for 2 weeks so wont have acess to this computer during that time, is it possible to carry out your next suggestions and post logs when i return or would my post have been deleted?, hope to hear back from you!

    oh and i do not run ANY disk emulation software on my pc currently!
     

    Attached Files:

    Last edited: Apr 12, 2010
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will give you a new fix below.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing. In fact, the below which is on your Desktop, looks like malware and I'm going to put it in the list of things to delete with Avenger.
    Code:
    "C:\Documents and Settings\Owner\Desktop\"
    n3uyezbc.exe  16 Dec 2009      293376  "n3uyezbc.exe"
    So if you know what this and don't want to loose it, save it somewhere else with a proper name to show what it is.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Owner\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. chaotix

    chaotix Private E-2

    hey Chaslang,
    i returned from my holiday in san francisco to face the horrors of the trojans once again, i have completed all as requested on your last post, and am attaching the current logs to this message, all the registry info integrated fine, however i am still getting the occassional random pop up occuring in firefox and internet explorer, let me know if any other problems with logs!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Occassional popups are likely due to what websites you are accessing. Your logs are clean. Make sure that you have the popup blocker feature for IE8 and FireFox enabled.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. chaotix

    chaotix Private E-2

    Hey Chaslang
    I have followed all instructions and ran virus and maware scans and all seemed clear, then next day i restart, do nothing except check emails on hotmail, close any random pop ups that arent blocked by the pop up blocker, and now my problem has jus got worse, internet explorer now opens up randomly on its own and directs me to adverts all the time i found the malicous process, deleted the file, however it keeps reappearing! the file is OM4dbTMm.exe any suggestions? jus when one thing gets removed i jus keep gettin attacked options are runnin out!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a new infection. Attach new logs from ComboFix and MGtools (obviously you need to redownload and run them again). You will have to shutdown McAfee to properly download and run these scans. Apparently it is not helping you anyway. Also please run the HelpAsst_mebroot_fix.exe fix I gave you in message # 6 again just to be safe.

    Previously I asked you about the below file and you did not respond to the question
     
    Last edited: May 14, 2010
  13. chaotix

    chaotix Private E-2

    Hey chaslang, thanks for your patience, in regards to that file that was an old file used to help fix a rootkit infection i had previously i simply never removed the file since it has now been removed completely!
    In regards to running combofix everytime i try and download it it says access is denied or cannot change the contents of the folder so download has failed??...
    i ran the root help assist thing, and MG tools and posted the MGtools logs with this message, wonder what could be wrong this time!
     

    Attached Files:

  14. chaotix

    chaotix Private E-2

    sorry i forgot to attach the help assist log to other post here it is!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run Defogger as requested in step 6 of the READ & RUN ME to disable your disk emulation software. You need to keep is disabled until we are all finished with cleanup. We need to make sure that we are not being tricked into seem an MBR infection by this. Now continue with the below.


    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now copy the bold text below to notepad. Save it as Fixha.bat to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it, find it and double click it and allow it to run it.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Owner\Local Settings\temp
    C:\WINDOWS\Tasks

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: May 15, 2010
  16. chaotix

    chaotix Private E-2

    hey chaslang
    thanks for the fast response, i have run tddskiller and MG tools attaching the logs now! not entirely sure if tddskiller managed to clear all from the log.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Looks like you may have missed my edit that added the Fixha.bat and Avenger steps. Please run them now.


    You have one of the new forms of TDL infections and will need to run the below to help us located the problem driver file.

    MaxLook - XP
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also don't miss the part about cleaning Temp folders and the Tasks folder
     
  19. chaotix

    chaotix Private E-2

    ok i ran that fixha.bat, no prompts came up but guess it worked, ran the avenger and restarted, i immediately got 1 error when windows started stating " windows cannot find C:\cleanup.exe, make sure typed correctly" along those lines, most files in avenger were deleted with the exception of 2 which surprise surprise popped up again, 1iEA88.dat and om4DbTMm.exe both in application data!
    cleared out all folders specified including tasks!
    ran maxlook and got a log posting this log, avengers log, MGtools log to this message! thanks for the help!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your Maxlook log, the program that is supposed to be protecting you is the source of your TDL infection. The below file is supposed to be part of McAfee but it has been replace by an infected file.
    Code:
    c:\windows\maxdriver\mfehidk.sys:
     Verified: Unsigned
     File date: 21:55 07/04/2010
     Publisher: n/a
     Description: n/a
     Product: n/a
     Version: n/a
     File version: n/a
    Uninstall McAfee immediately and then reboot your PC and run the below to be sure McAfee is removed.

    McAfee Consumer Product Removal Tool

    Now see if the below file exists and if it does, see if you can delete it:

    c:\windows\system32\drivers\mfehidk.sys


    If the below file is now gone then continue with the below.

    Run TDSSkiller again.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. chaotix

    chaotix Private E-2

    Hey Chaslang,
    Jus woke up and did as you asked, i uninstalled mcafee and cleared all files, and yes that driver was still there, i was able to delete it, ran tddskiller, seems all infections are now cleared, but will post the log so u can see for yourself, ran mgtools and have a log also will post that as well! also now that im without an antivirus can u suggest any good ones i can get hold of?, i also have access to kasperskys which i am willing to pay for if its good.
    how can i be sure simple browsing now wont leave me with more infections, is there a way to check if this virus has infecteed me with others??
    hope to hear from you soon
    also just to add mate when i look at my system processes, even though just one internet explorer is working i have 3 iexplore.exe processes running is this normal?
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent. Now that we have the main part of you problem fixed and also now that we have McAfee out of our way, we will again try using ComboFix to finish off a few things.

    You can purchase Kaspersky if you wish. It is a well known program. Or you can use free tools as given in our sticky threads; however, do not install anything yet. I do not want them to get in our way. Hopefully we are just about finished. Just keep your additional surfing and online game playing to zero until we finish.

    That is why we have you run thru the READ & RUN ME process. ;)

    Normal. All new tabbed browsers will show multiple processes. Some ( like Google Chrome ) may even show 7 to 10 processes depending on the number of tabs.


    Please download the current version of combofix.exe to your Desktop.

    Now we need to use ComboFix as instructed below.
    • Double check to be sure that combofix.exe is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  23. chaotix

    chaotix Private E-2

    Hey Chaslang
    I ran combofix using the notepad method it worked, cleared all those temp folders, ran cccleaner, and MG tools the logs for these are attached to ths message, things seem to be looking promising however, earlier once again the 1iEA88.bat and om4DbTmm.exe popped up but after removing them they have not appaeared again... so far, i really jus hope they are gone..
    here are the logs
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes which is why I wanted to get ComboFix to run. Did you notice it was deleting some of the files related to your startup processes? Many are infected. You may need to reinstall some software, but first let's see if we can fix some of these by uninstalling a few and then running another round with ComboFix.

    So uninstall the below now:
    • SUPERAntiSpyware
    • Yahoo Messenger

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    Code:
    Driver::
    ethrenky
    
    RenV::
    c:\program files\Yahoo!\Messenger\YahooMessenger .exe
    c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate .exe ---^> c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe ---^> c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe ---^> c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    c:\program files\Common Files\Java\Java Update\jusched .exe ---^> c:\program files\Common Files\Java\Java Update\jusched.exe
    c:\program files\CyberLink\PowerDVD\PDVDServ .exe ---^> c:\program files\CyberLink\PowerDVD\PDVDServ.exe
    c:\program files\CyberLink\PowerDVD\Language\Language .exe ---^> c:\program files\CyberLink\PowerDVD\Language\Language.exe
    c:\program files\Electronic Arts\EADM\Core .exe ---^> c:\program files\Electronic Arts\EADM\Core.exe
    c:\program files\Intel Audio Studio\IntelAudioStudio .exe ---^> c:\program files\Intel Audio Studio\IntelAudioStudio.exe
    
    Folder::
    c:\program files\SUPERAntiSpyware
    
    File::
    c:\windows\system32\opaqcx.dll
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Messenger (Yahoo!)"=-
    "SUPERAntiSpyware"=-
    "Google Update"=- 
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  25. chaotix

    chaotix Private E-2

    Hey Chaslang
    i have run the required script in combofix and MGtools has been run i am attaching all logs with this response, after boot up this morning i have had no mysterious pop ups occure (yet), keeping fingers crossed!
    thanks for all the help finally feel like progress is being made!
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good to me.

     
  27. chaotix

    chaotix Private E-2

    Hey Chaslang and Timw
    just wanted to say a huge thank you to both of you, from what i can see i have no more annoying files, no more random windows opening, all my scans are coming back as clean now and i have taken measures to ensure i have proper protection on my machine! thanks for all your help you saved me a lot of trouble!
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds